Friday, 22 July 2011

So, do we actually care?

One of the consequences of the recent rash of published hacking incidents is that we may now have a contemporary sample size that's almost big enough to draw some meaningful conclusions about how much the general populace (and business) actually cares about information security. Incidents associated with Anonymous, LulzSec, Sony, RSA, News International and others are all now in the public consciousness. But will there be any real long-term impact of these hacks? For example:

How many mobile phone users have now set unique PINs on their voicemail rather than relying on the default values?

How many organisations have ditched their RSA tokens in favour of competing technologies?

How many PS3 users have abandoned the PlayStation Network for good? Or have they all (like me :-) been bought off by a few free games and promises that it'll be better next time?

If consumers don't actually care about security, what are the real drivers for continuing to invest in it? Do we really have to fall back on compliance as the sole driver?

It's fortunate for the security industry that there are still financial services organisations, IP-centric industries, gaming firms etc where the security of their systems and data is necessary for their continued survival.

But hey, I could be wrong and perhaps the recent incidents will drive new and improved behaviours - guess we'll just have to wait and see...

Wednesday, 22 June 2011

LulzSec

LulzSec - doing it for the lulz. Looking at the attention and drama they've created, can anyone say that they haven't succeeded?

Friday, 3 June 2011

Time for RSA to come clean

Right. I've been patient. We've all been patient. But now I think it's time that RSA come clean about exactly what they lost when they were compromised earlier this year. We've now had reported attacks against Lockheed Martin, L-3 Communications and Northrop Grumman all of which have been linked with the use of SecurID tokens as an attack vector. Is the reporting correct? No idea. Is damage being done to RSA regardless? Oh yes.

What harm can come now from RSA posting details of what was compromised? I'm aware that RSA are in talks with their bigger customers but I don't think that this is enough. It certainly doesn't help me if I'm considering implementing a new two-factor authentication solution; why on earth would I consider SecurID at this time?

Final points to consider. It's probably fair to state now that whomever compromised RSA has used that information to attack their first tranche of targets. The surprise element is now gone and top tier targets should now be on the lookout for similar incursions. So what's the value now to the attackers in keeping whatever they got from RSA close to their chests? I daresay there'll be a bit of probing of some of their second tier targets (banks anyone?) before the attackers decide that they've realised most of the value of their initial RSA compromise. Depending on how mischievous they feel, I wouldn't necessarily be surprised to see the compromised RSA materials appear on the Internet in the near future - if only as a means to cause significant pain and disruption to the rest of the RSA user base. Do state-sponsored hackers still do it for the lulz? Guess we'll find out soon enough.

*********UPDATED************

Open letter from RSA to their customers:

http://www.rsa.com/node.aspx?id=3891

Still no real details though. Ho hum.

Tuesday, 10 May 2011

PSN hack

O... M... G...

http://www.eweek.com/c/a/Security/Sony-Networks-Lacked-Firewall-Ran-Obsolete-Software-Testimony-103450/

I'm surprised they weren't hacked sooner.

The content of the article does raise some really interesting questions about their compliance with PCI-DSS and how they got through the process...

Tuesday, 26 April 2011

Thoughts on Infosec and the AWS outage

I managed to sneak in a quick afternoon visit to Infosec last Wednesday. I'll admit the free (and, quite honestly, excellent) lunch that I'd been invited to by the chaps over at IRM was influential in making sure that I didn't miss the show completely this year. Good food, interesting conversation. Thanks Phil :-)

I'm not entirely sure what I made of this year's show. To my eyes, it seemed quite busy in terms of attendee numbers and a number of the brave souls manning the stands seemed to be losing their voices by the time I got there after lunch. Which means it's probably safe to assume that they'd been kept occupied pitching their wares and handing over the usual treasure trove of pens, t-shirts and cheap puzzles. However. Other than finding out some more positive details on the Forum Systems products and coming across a promising new cloud security vendor (CipherCloud - check 'em out!) I'm not sure that I got too much out of the exhibition. Primarily the same old(er) faces pitching the same old(er) solutions and, unfortunately, the same can probably said of the education streams. Can't help thinking that the information security scene needs an injection of new DNA to breathe some new life, enthusiasm and ideas into what seems to be becoming a somewhat jaded, self-serving and self-congratulatory sector. The irony of my posting that last statement on a blog has not escaped me :-)

Whilst I'm being a little negative, the big story from the cloud computing world has been the downtime over at AWS which even made it on to the BBC web-site: http://www.bbc.co.uk/news/technology-13160929. We're still awaiting details of the problem (other than that there was a problem with EBS volumes and dependent services) but the biggest surprise(?) was that the issue spanned supposedly isolated availability zones within the affected region. I'm really hoping that the promised "post-mortem" discussing this event provides sufficient detail to enable AWS customers to design for resilience with a full understanding of exactly how isolated availability zones really are...

Friday, 8 April 2011

Latest cloudy ramblings

See, I'm making the most of my recently discovered free(ish!) time by popping up in Computer Weekly talking about the adoption of cloud services by SMEs. Link below:

http://www.computerweekly.com/Articles/2011/04/06/246204/CW-Security-Think-Tank-Whats-holding-up-the-cloud.htm

Some interesting differences in tone and opinions amongst the contributors to this Think Tank piece. When it comes to the use of hybrid cloud models I think I tend more towards the opinions expressed by Christofer Hoff over at http://www.rationalsurvivability.com/blog/?p=3016 rather than the view expressed by the chap from Gartner that cloud providers should be targetting SMEs with hybrid cloud services.

Hybrid is fine if you're talking about mixing your delivery of capabilities across on-premise and cloud, I've always had more of a problem with Hybrid as a way of delivering increased capacity on demand in that it's always seemed the worst of both worlds from a security perspective, i.e. you need to worry about the security problems associated with both models rather than just the one!

And, as Hoff says, "If your Tier-1 workloads can run in a public cloud and satisfy all your requirements, THAT’S where they should run in the first place!"

Friday, 25 March 2011

Fair warning

Wow. Where did Q1 go? Not on blogging obviously :-)

Well, after four years on one assignment I finally get to try something new from the end of next week. It's been a primarily fun and worthwhile four years and I've met some good people in that time (just in case any of my current colleagues are reading!) but it's been tough and I'm looking forward to a new challenge. I'm also looking forward to an assignment that will give me a bit more time to concentrate on this blog and posting a little more regularly than once a quarter.

So, what prompted me to come out of blogging hibernation? High profile hacks! By which I'm thinking HBGary Federal, RSA and Comodo. I can't remember a time when three such hacks happened in such a short space of time and received this amount of publicity. Which is the most interesting? Hard to say. HBGary Federal was interesting because of the contents of the email spool that Anonymous released and the somewhat embarrassing implications for the likes of Bank of America and Morgan Stanley.

Is RSA interesting? Hard to tell as they've been very quiet about what was actually accessed during their compromise and so their customers are in limbo. So, it's interesting in so far as a high profile security firm got 0wned; likely to be more interesting once it becomes apparent what was purloined by the attackers. C'mon RSA, help us all out here!

But the Comodo hack; now that is certainly interesting. See http://www.comodo.com/Comodo-Fraud-Incident-2011-03-23.html for details. Almost certainly laying the foundations of a larger hack and demonstrating why the core security measure for most Internet users (SSL) should not be relied upon as strongly as it currently is - it certainly shows that certificate authentication is worthless without strong registration processes and capable registration authorities. To be fair however, and in direct contrast to RSA, Comodo have at least been forthright in explaining the implications of the hack and the certificates issued.

Anyone can get hacked, including those we trust to secure the Internet, so here's hoping that more organisations follow the Comodo approach to notification than the RSA approach.

See you in Q3 :-)